Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5.0, <= 10.5.10
- >= 10.11.0, <= 10.11.2
A vulnerability exists in Mattermost versions 10.5.x through 10.5.10 and 10.11.x through 10.11.2, where sensitive string comparisons are not performed in constant time. This flaw enables attackers to exploit timing oracles, conducting byte-by-byte brute force attacks by analyzing response times on Cloud API keys and OAuth client secrets.
Exploitation of this vulnerability could lead to successful brute force attacks on Cloud API keys and OAuth client secrets, allowing attackers to gain unauthorized access or perform actions on behalf of users.
Users can upgrade to Mattermost version 11.0.0 or 10.12.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.